A terminal device of an embodiment of the present disclosure comprises: a first acquisition means that measures the body or voice of a user when the user is to be authenticated, and acquires first biological information, which is biological information corresponding to the measurement result; a second acquisition means that acquires second biological information, which is biological information corresponding to the body or voice of a person and stored in an information storage medium, and an electronic certificate indicating the authenticity of the person; an authentication means for performing user authentication by comparison based on the first biological information and the second biological information; and a transmission means for transmitting the acquired electronic certificate and authentication result if the user has been authenticated.
Legal claims defining the scope of protection, as filed with the USPTO.
a memory; and at least one processor coupled to the memory the at least one processor performing operations to: a measure a body or voice of a user when authenticating the user; acquire first biological information, the first biological information being biological information according to a result of the measurement; acquire second biological information and an electronic certificate indicating authenticity of a person, the second biological information being biological information relevant to a body or voice of the person, the second biological information and the electronic certificate being stored in an information storage medium; authenticate the user by comparison based on the first biological information and the second biological information; and transmit the acquired electronic certificate and an authentication result when the user is authenticated. . A terminal device comprising:
claim 1 when the user is not authenticated, transmit the first biological information and the second biological information to a server capable of performing authentication processing, receive information indicating a result of the authentication processing based on the first biological information and the second biological information, and when the received result indicating the user has been authenticated, transmit the electronic certificate. . The terminal device according to, wherein the at least one processor further performs operation to:
claim 1 measure the body or voice of the user operating the terminal device at a timing different from a timing at which the first biological information is acquired, and acquire third biological information, the third biological information being biological information according to a result of the measurement, and authenticate the user by comparison based on the first biological information and the third biological information. . The terminal device according to, wherein the at least one processor further performs operation to:
claim 1 transmit the electronic certificate and the authentication result to a server accepting a procedure performed by the user, and receive implementation status information indicating an implementation status of the procedure based on the electronic certificate and the authentication result that have been transmitted. . The terminal device according to, wherein the at least one processor further performs operation to:
claim 1 generate document information associated with the procedure, and transmit the document information when the user is authenticated. . The terminal device according to, wherein the at least one processor further performs operation to:
claim 5 encrypt the document information, acquire a private key and a public key relevant to the private key stored in the information storage medium, encrypt the document information based on the private key, and when the user is authenticated, transmit the public key and the encrypted document information. . The terminal device according to, wherein the at least one processor further performs operation to:
claim 5 when the user is not authenticated, temporarily store the generated document information. . The terminal device according to, wherein the at least one processor further performs operation to:
in a terminal operated by a user, measuring a body or voice of the user when authenticating the user; acquiring first biological information, the first biological information being biological information according to a result of the measurement; acquiring second biological information and an electronic certificate indicating authenticity of a person, the second biological information being biological information relevant to a body or voice of the person, the second biological information and the electronic certificate being stored in an information storage medium; authenticating the user by comparison based on the first biological information and the second biological information; and transmitting the acquired electronic certificate and an authentication result when the user is authenticated. . An identity verification assistance method comprising:
in a terminal operated by a user, measuring a body or voice of the user when authenticating the user; acquiring first biological information, the first biological information being biological information according to a result of the measurement; acquiring second biological information and an electronic certificate indicating authenticity of a person, the second biological information being biological information relevant to a body or voice of the person, and an electronic certificate indicating authenticity of the person, the second biological information and the electronic certificate being stored in an information storage medium; authenticating the user by comparison based on the first biological information and the second biological information; and transmitting the acquired electronic certificate and an authentication result when the user is authenticated. . A non-transitory computer-readable storage medium storing a program for executing a process comprising:
Complete technical specification and implementation details from the patent document.
The present disclosure relates to a technique of supporting identity verification in a procedure via a network.
Services that allow consumers to perform procedures online are generally provided in various business types such as finance, insurance, real estate, retail, infrastructure, and the like. A technique for performing identity verification in such a situation is disclosed.
PTLs 1 and 2 disclose a method of performing identity verification at a time of opening an account of a financial institution from a terminal owned by a user.
Specifically, the information processing device according to PTL 1 images the face of the user and a license of the user in the terminal.
Then, the information processing device compares the captured facial image of the user with the captured facial image of the license, and determines whether the action of the user corresponds to a predetermined action, thereby performing identity verification.
The identity verification system according to PTL 2 outputs a guide screen designating an arrangement position of an object to be captured together with an identity verification document. Then, the identity verification system compares an identity verification image including the identity verification document captured in accordance with the guide screen with a collation image, which is separately captured and includes a face of an owner of the identity verification document, thereby performing identity verification.
PTL 1: WO 2020/022014 A 1
PTL 2: JP 2020-161191 A
At a time of performing identity verification by face matching, a captured facial image of a user may be compared with a captured image of an official certificate attached with a facial portrait. At this time, the comparison may not be accurately carried out depending on a state of the surface of the official certificate, quality of the captured image, and the like. A third party other than the legitimate user may impersonate the legitimate user by using a forged identity verification document or the like.
The present disclosure has been conceived in view of the problems described above, and an object of the present disclosure is to provide a terminal device and the like capable of appropriately performing identity verification.
A terminal device according to an aspect of the present disclosure includes a first acquisition means for measuring a body or voice of a user at when authenticating the user and acquiring first biological information, the first biological information being biological information according to a result of the measurement, a second acquisition means for acquiring second biological information and an electronic certificate indicating authenticity of a person, the second biological information being biological information relevant to a body or voice of the person, the second biological information and the electronic certificate being stored in an information storage medium, an authentication means for authenticating the user by comparison based on the first biological information and the second biological information, and a transmission means for transmitting the acquired electronic certificate and an authentication result when the user is authenticated.
An identity verification assistance method according to an aspect of the present disclosure includes, in a terminal operated by a user, measuring a body or voice of the user when authenticating the user and acquiring first biological information, the first biological information being biological information according to a result of the measurement, acquiring second biological information and an electronic certificate indicating authenticity of a person, the second biological information being biological information relevant to a body or voice of the person, the second biological information and the electronic certificate being stored in an information storage medium, authenticating the user by comparison based on the first biological information and the second biological information, and transmitting the acquired electronic certificate and an authentication result when the user is authenticated.
A computer-readable storage medium according to an aspect of the present disclosure stores a program for executing a process including, in a terminal operated by a user, measuring a body or voice of the user when authenticating the user and acquiring first biological information, the first biological information being biological information according to a result of the measurement, acquiring second biological information, and an electronic certificate indicating authenticity of a person, the second biological information being biological information relevant to a body or voice of the person, and an electronic certificate indicating authenticity of the person, the second biological information and the electronic certificate being stored in an information storage medium, authenticating the user by comparison based on the first biological information and the second biological information, and transmitting the acquired electronic certificate and an authentication result when the user is authenticated.
According to the present disclosure, identity verification may be appropriately performed.
Hereinafter, example embodiments of the present disclosure will be described with reference to the drawings.
An outline of a terminal device according to the present disclosure will be described. The terminal device is used to carry out identity verification of a user. Specifically, the user performs, using the terminal device, a predetermined procedure with respect to a service provider.
The predetermined procedure may relate to, for example, a transaction with a financial institution, an insurance application, a product purchase, or the like. The predetermined procedure is not limited to those examples. At this time, the terminal device performs identity verification of the user.
1 FIG. 100 100 100 is a block diagram illustrating an exemplary functional configuration of a terminal device. The terminal deviceis a terminal used by the user. The terminal deviceis, for example, a portable terminal such as a smartphone, a tablet terminal, or the like.
100 100 100 The terminal deviceis not limited to this example, and may be a personal computer. The terminal devicehas a camera function. The terminal devicefurther includes input/output equipment. Examples of the input/output equipment include a keyboard, a microphone, a display, a speaker, an integrated circuit (IC) card reader, and the like.
100 110 120 130 140 The terminal deviceincludes a first acquisition unit, a second acquisition unit, an authentication unit, and a transmission unit.
110 110 100 110 The first acquisition unitacquires biological information of the user at a time of authenticating the user. The biological information is information relevant to a living body. A face is an example of the living body, but the living body is not limited to this example. The living body may indicate a body or voice of a person. The first acquisition unitacquires biological information according to a result of measurement of the living body. An example of the measurement is imaging. For example, the face of the user is captured by the terminal device. The first acquisition unitmay acquire a facial image acquired by imaging the face of the user as the biological information. Such biological information according to the result of the measurement of the living body will be referred to as first biological information.
110 110 In this manner, the first acquisition unitmeasures the body or voice of the user when authenticating the user, and acquires the first biological information, the first biological information being biological information according to a result of the measurement. The first acquisition unitis an example of a first acquisition means.
120 The second acquisition unitacquires information stored in an information storage medium. The information storage medium stores biological information and an electronic certificate. The biological information stored in the information storage medium will be referred to as second biological information. The second biological information is biological information relevant to the living body of the person. For example, the second biological information is a facial image of the person. The electronic certificate is information indicating authenticity of the person. For example, the electronic certificate is issued by an external certificate authority or the like. Examples of the information storage medium include an official certificate equipped with an IC chip.
The second biological information is, for example, a facial image of the person shown on the official certificate. That is, the information storage medium stores second biological information of a predetermined person and an electronic certificate indicating authenticity of the predetermined person.
100 120 100 In this case, in the terminal device, the second biological information and the electronic certificate stored in the information storage medium are read by an IC card reader function. The second acquisition unitmay acquire the read second biological information and electronic certificate. The information storage medium may be a storage device mounted on the terminal device.
120 120 In this manner, the second acquisition unitacquires the second biological information and the electronic certificate indicating the authenticity of the person, the second biological information being biological information relevant to the body or voice of the person, the second biological information and the electronic certificate are stored in the information storage medium. The second acquisition unitis an example of a second acquisition means.
130 130 130 130 The authentication unitauthenticates the user. Specifically, the authentication unitcarries out comparison based on the first biological information and the second biological information. For example, the authentication unitcompares a feature regarding the face extracted from the first biological information with a feature regarding the face extracted from the second biological information. If the comparison matches, the authentication unitauthenticates the user. The authentication method is not limited to this example. For example, the user may be authenticated by a method of calculating similarity of the entire image, such as pattern matching.
130 130 In this manner, the authentication unitauthenticates the user by the comparison based on the first biological information and the second biological information. The authentication unitis an example of an authentication means.
140 130 140 140 The transmission unittransmits various types of information. Specifically, when the user is authenticated by the authentication unit, the transmission unittransmits the acquired electronic certificate and the authentication result. The authentication result includes information indicating whether the user is authenticated. The transmission unitmay transmit the electronic certificate and the authentication result to a provider server. The provider server may be a server operated by a service provider, which is a target of the procedure performed by the user. For example, it is assumed that the user performs a procedure for opening an account of a financial institution online. In this case, the provider server is a server operated by the financial institution or an institution entrusted by the financial institution.
140 140 As described above, when the user is authenticated, the transmission unittransmits the acquired electronic certificate and the authentication result. The transmission unitis an example of a transmission means.
100 1 2 FIG. Next, exemplary operation of the terminal devicewill be described with reference to. In the present disclosure, each step of a flowchart is represented using a number assigned to each step, such as “S”.
2 FIG. 100 110 1 120 2 130 3 140 4 is a flowchart for explaining exemplary operation of the terminal device. The first acquisition unitmeasures the body or voice of the user at the time of authenticating the user, and acquires the first biological information, which is biological information according to a result of the measurement (S). The second acquisition unitacquires the second biological information that is biological information relevant to the body or voice of the person and the electronic certificate indicating the authenticity of the person, which are stored in the information storage medium (S). The authentication unitauthenticates the user by comparison based on the first biological information and the second biological information (S). When the user is authenticated, the transmission unittransmits the acquired electronic certificate and the authentication result (S).
100 100 100 100 As described above, the terminal deviceaccording to the first example embodiment measures the body or voice of the user at the time of authenticating the user, acquires the first biological information being the biological information according to the result of the measurement. Further the terminal deviceacquires the second biological information and the electronic certificate indicating the authenticity of the person, the second biological information being the biological information relevant to the body or voice of the person, the second biological information and the electronic certificate being stored in the information storage medium. The terminal deviceauthenticates the user by the comparison based on the first biological information and the second biological information. Then, when the user is authenticated, the terminal devicetransmits the acquired electronic certificate and the authentication result.
100 100 In a case of performing the identity verification using a captured image of an official certificate attached with a facial portrait, the identity verification may not be accurately carried out if the surface of the official certificate is damaged. On the other hand, the terminal deviceaccording to the first example embodiment uses the biological information including the electronic certificate indicating the authenticity of the person stored in the information storage medium. Thus, the terminal deviceis enabled to carry out the identity verification without considering the state of the surface of the official certificate.
100 100 100 The terminal deviceis capable of performing authentication based on possession of the information storage medium storing the electronic certificate described above and performing authentication using the biological information stored in the information storage medium. Thus, the terminal deviceis enabled to reduce the risk of impersonation due to forgery of an official certificate or the like. That is, the terminal deviceaccording to the first example embodiment is capable of appropriately performing the identity verification.
100 Next, an identity verification assistance system including a terminal device according to a second example embodiment will be described. In the second example embodiment, the terminal devicedescribed in the first example embodiment will be described in more detail. Description of contents overlapping with the contents described in the first example embodiment will be partially omitted.
In the second example embodiment, a situation will be described as an example in which a user performs a procedure for a financial institution online. More specifically, in the second example embodiment, it is assumed that the user performs a procedure for opening an account of a financial institution using the terminal device. The exemplary procedure to be described in the present example embodiment is merely an example. The identity verification assistance system according to the present disclosure is applicable to various procedures.
3 FIG. 1000 is a diagram schematically illustrating an exemplary configuration including an identity verification assistance system.
1000 100 200 The identity verification assistance systemincludes a terminal deviceand a provider server.
100 200 300 200 200 200 The terminal deviceis communicably connected to the provider serverand a verification servervia a network. The provider serveris a server managed by a service provider. For example, the provider serveris managed by a financial institution or an institution entrusted by the financial institution. The provider serveraccepts a procedure performed by the user. That is, the provider server receives an application for account opening.
300 300 The verification serveris a server that verifies validity of an electronic certificate. For example, the verification serveris a server managed by an institution, such as an external certificate authority, that manages electronic certificates.
100 100 100 For example, the user activates a dedicated application stored in the terminal deviceto perform the procedure for opening an account. The processing of the terminal devicemay be executed by the application. The user may activate a browser on the terminal device, access a website of the financial institution, and perform the procedure for opening an account.
4 FIG. 1000 100 110 120 130 140 100 150 160 170 180 is a block diagram illustrating an exemplary functional configuration of the identity verification assistance system. The terminal deviceincludes a first acquisition unit, a second acquisition unit, an authentication unit, and a transmission unit. The terminal devicefurther includes a document generation unit, an encryption unit, a receiving unit, and an imaging unit.
110 180 100 110 180 The first acquisition unitacquires first biological information of the user. Specifically, the face of the user is imaged by the imaging unitof the terminal device. The first acquisition unitacquires, from the imaging unit, a captured image acquired by imaging the face of the user.
120 The second acquisition unitacquires information stored in an information storage medium. The information storage medium may be an official certificate. An individual number card is an example of the information storage medium. The individual number card is equipped with an IC chip. The IC chip stores a facial image of the owner of the individual number card and an electronic certificate. The IC chip further includes a public key. The electronic certificate includes an electronic certificate for signatures and an electronic certificate for user certification.
The electronic certificate for signatures is used at a time of creating or transmitting document information on the Internet or the like. The electronic certificate for signatures is information indicating that the document information is authentic and created by the owner of the individual number card. The electronic certificate for signatures includes a private key for signatures and four pieces of basic information of the owner. The private key is relevant to the public key included in the IC chip. That is, information encrypted with the private key is decrypted with the public key. The four pieces of basic information indicates a name, an address, a date of birth, and a gender. The electronic certificate for user certification is information indicating the user him/herself. The electronic certificate for user certification includes a private key for user certification.
120 100 The second acquisition unitacquires at least the electronic certificate for signatures and the facial image of the owner, which are stored in the IC chip of the individual number card. The facial image of the owner is an example of second biological information. At this time, the terminal deviceperforms contactless communication, whereby information is read from the individual number card.
5 FIG. 5 FIG. 5 FIG. 100 100 120 100 100 100 120 is a diagram illustrating an exemplary situation in which information is read from the information storage medium. The terminal devicereads information stored in the information storage medium by contactless communication. For example, the information is read by near field communication (NFC) technology. The example ofillustrates an exemplary case where the terminal devicereads information from the individual number card. At this time, the second acquisition unitmay output guidance information for guiding an operation of reading the information from the information storage medium. In the example of, the text “Please hold up your individual number card” is shown on the display of the terminal deviceas the guidance information. For example, the user holds the individual number card over the terminal devicein accordance with the guidance information shown on the display. As a result, the terminal devicereads the facial image and the electronic certificate for signatures from the individual number card. In this manner, the second acquisition unitmay acquire the facial image and the electronic certificate for signatures by reading the facial image and the electronic certificate for signatures from the information storage medium.
120 100 120 100 120 120 100 100 The second acquisition unitmay prompt for a passcode input when the operation of reading the information is performed. For example, after the user holds the individual number card over the terminal device, the second acquisition unitreceives the passcode input from the user. In this case, registration number information indicating the correct passcode is stored in the IC chip or in a storage device (not illustrated) included in the terminal device. When the input passcode matches the registration number information, the second acquisition unitmay read the information from the individual number card. When the input passcode does not match the registration number information, the second acquisition unitmay prompt for the passcode input again, or may output information indicating failure in reading the information in the terminal device. As described above, by using the passcode at the time of acquiring the information from the information storage medium, the terminal deviceis further enabled to perform knowledge authentication.
120 120 100 100 The method of acquiring the information by the second acquisition unitis not limited to this example. For example, the second acquisition unitmay acquire various types of information by contact-type communication performed in the terminal device. In this case, a terminal of a card reader communicably connected to the terminal deviceand the IC chip of the individual number card come into contact with each other, whereby information is read.
120 120 While the exemplary case where the information storage medium is the individual number card has been mainly described above, the information storage medium is not necessarily the individual number card. It is sufficient if the information storage medium is an official certificate equipped with an IC chip storing a facial image and an electronic certificate as described above. The second acquisition unitmay acquire the public key from the information storage medium in a similar manner. In the case where the information storage medium is an individual number card, the second acquisition unitmay acquire the electronic certificate for user certification in a similar manner.
130 110 120 130 130 130 130 130 The authentication unitauthenticates the user based on the first biological information acquired by the first acquisition unitand the second biological information acquired by the second acquisition unit. Specifically, the authentication unitcompares a captured image acquired by imaging the face of the user with the facial image stored in the information storage medium. At this time, for example, the authentication unitextracts a feature of the face from the captured image (first biological information). The authentication unitfurther extracts a feature of the face from the facial image (second biological information). Then, the authentication unitcompares the extracted features. A match of the comparison indicates that the user has been authenticated. A mismatch of the comparison indicates that the user has not been authenticated. The authentication unitgenerates an authentication result. A general facial matching technique may be used as a method of authenticating the user.
140 130 140 200 120 130 140 200 The transmission unittransmits various types of information. When the user is authenticated by the authentication unit, the transmission unittransmits, to the provider server, the electronic certificate acquired by the second acquisition unitand the authentication result generated by the authentication unit. At this time, the transmission unitfurther transmits, to the provider server, the public key and encrypted document information to be described later.
140 300 300 140 200 The transmission unitfurther transmits the electronic certificate to the verification server. As a result, the verification serververifies the validity of the electronic certificate. When the user is authenticated and the validity of the electronic certificate is verified, the transmission unitmay transmit the authentication result and the electronic certificate to the provider server.
130 140 200 200 When the user is not authenticated by the authentication unit, the transmission unitmay transmit the first biological information and the second biological information to the provider server. In this case, the provider serverperforms authentication processing. The authentication processing by the provider server will be described later.
150 150 150 The document generation unitgenerates document information associated with a procedure. The document generation unitis an example of a document generation means. The document information indicates a document associated with the procedure. In the case where the procedure performed by the user is account opening, the document information is an account opening application form. The document generation unitreceives an input operation from the user, and generates document information to which information according to the input operation is input.
160 160 160 120 160 The encryption unitencrypts the document information. The encryption unitis an example of an encryption means. Specifically, the encryption unitencrypts the document information using the private key included in the electronic certificate acquired by the second acquisition unit. In the case where the information storage medium is an individual number card, the encryption unitencrypts the document information using the private key for signatures.
170 170 170 200 170 100 The receiving unitreceives various types of information. The receiving unitis an example of a receiving means. The receiving unitreceives implementation status information from the provider server. The receiving unitoutputs the received implementation status information to the terminal device. Details of the implementation status information will be described later.
170 300 The receiving unitfurther receives a verification result regarding the validity of the electronic certificate from the verification server.
200 210 220 230 210 100 210 100 210 210 200 The provider serverincludes a reception unit, a notification unit, and an authentication unit. The reception unitreceives information transmitted from the terminal device. For example, the reception unitreceives, from the terminal device, the authentication result, the encrypted document information, the electronic certificate, and the public key. When the reception unitreceives the encrypted document information and the public key, the reception unitdecrypts the document information using the public key. As a result, the provider serveraccepts the procedure. Descriptions of an examination of the procedure based on the contents of the document information will be omitted.
210 100 230 The reception unitmay further receive the first biological information and the second biological information from the terminal device. In this case, the authentication unitcarries out the authentication processing.
230 230 230 The authentication unitextracts a feature regarding the face from each of the received first biological information and second biological information. Then, the authentication unitcarries out the authentication processing by comparing the extracted features. The authentication unitgenerates an external authentication result indicating a result of the authentication processing.
220 100 220 100 The notification unitmakes various types of notification to the terminal device. Specifically, the notification unittransmits the implementation status information to the terminal device. The implementation status information indicates an implementation status of the procedure based on the electronic certificate and the authentication result. For example, the implementation status information may indicate completion of the procedure, or may indicate incompletion of the procedure due to some deficiencies.
220 100 The notification unitmay further transmit the external authentication result to the terminal device.
1000 100 200 Exemplary operation of the identity verification assistance systemwill be described. In the present exemplary operation, operation of each of the terminal deviceand the provider serverwill be described.
6 FIG.A 100 100 101 150 102 is a flowchart for explaining first exemplary operation of the terminal device. First, an application is activated in the terminal deviceby an operation made by the user (S). Examples of the application include an application for opening an account. The document generation unitgenerates document information associated with a procedure (S). The document information is information to which information according to the input operation made by the user is input.
100 120 100 120 103 104 120 105 120 104 120 Next, the terminal devicereads information from the information storage medium. Specifically, an information reading function is activated by a user operation. At this time, the second acquisition unitoutputs guidance information for guiding an operation of reading information. The user holds the information storage medium over the terminal devicein accordance with the guidance information. The second acquisition unitreceives an input of a passcode (S). If the input passcode is correct (“Yes” in S), the second acquisition unitacquires various types of information from the information storage medium (S). For example, the second acquisition unitacquires an electronic certificate, a facial image, and a public key. The facial image corresponds to the second biological information. If the input passcode is incorrect (“No” in S), the second acquisition unitmay receive the passcode input again. At this time, the process may be terminated if the passcode is input a predetermined number of times but remains incorrect.
140 300 106 300 170 300 107 100 107 180 108 After the processing of S105, the transmission unittransmits the electronic certificate to the verification server(S). As a result, the verification serververifies the validity of the electronic certificate. Then, the receiving unitreceives a verification result regarding the validity of the electronic certificate from the verification server. If the validity of the electronic certificate is not verified (“No” in S), the terminal devicemay terminate the process. If the validity of the electronic certificate is verified (“Yes” in S), the imaging unitimages the face of the user (S).
110 180 109 130 110 130 105 109 130 The first acquisition unitacquires, as the first biological information, the captured image imaged by the imaging unit(S). The authentication unitcarries out authentication processing (S). Specifically, the authentication unitextracts a feature of the face from each of the second biological information acquired in the processing of Sand the first biological information acquired in the processing of S. Then, the authentication unitcarries out the authentication processing by comparing the extracted features.
111 130 112 160 113 If the user is authenticated (“Yes” in S), the authentication unitgenerates an authentication result indicating that the user has been authenticated (S). The encryption unitencrypts the document information using the private key included in the electronic certificate (S).
140 200 114 140 The transmission unittransmits, to the provider server, the electronic certificate, the authentication result, the encrypted document information, and the public key (S). At this time, the transmission unitmay transmit the encrypted document information and the document information before being encrypted.
170 200 115 The receiving unitreceives the implementation status information from the provider server(S).
111 111 100 6 FIG.B If the user is not authenticated in the processing of S(“No” in S), the terminal deviceperforms a process illustrated in.
6 FIG.B 100 130 116 140 200 117 is a flowchart for explaining second exemplary operation of the terminal device. At this time, the authentication unitgenerates an authentication result indicating that the user has not been authenticated (S). The transmission unittransmits, to the provider server, the first biological information, the second biological information, and the authentication result (S).
170 200 118 119 160 120 140 200 121 170 200 122 The receiving unitreceives the external authentication result from the provider server(S). If the external authentication result indicates that the user has been authenticated (“Yes” in S), the encryption unitencrypts the document information using the private key included in the electronic certificate (S). The transmission unittransmits, to the provider server, the electronic certificate, the authentication result, the encrypted document information, and the public key (S). Then, the receiving unitreceives the implementation status information from the provider server(S).
119 119 100 If the external authentication result indicates that the user has not been authenticated in the processing of S(“No” in S), the terminal devicemay terminate the process.
150 In each case where the user has not been authenticated, the document generation unitmay temporarily store the generated document information.
200 200 200 100 114 7 FIG.A 7 FIG.A Next, exemplary operation of the provider serverwill be described.is a flowchart for explaining first exemplary operation of the provider server. Specifically,illustrates an operation to be performed by the provider serverafter the terminal deviceperforms the processing of S.
210 200 100 201 210 202 220 203 200 220 220 220 100 204 100 115 The reception unitof the provider serverreceives, from the terminal device, the electronic certificate, the authentication result, the encrypted document information, and the public key (S). The reception unitdecrypts the encrypted document information using the public key (S). The notification unitgenerates implementation status information (S). For example, when the provider serverduly accepts the procedure, the notification unitgenerates implementation status information indicating completion of the procedure. For example, when there is a deficiency in the procedure, the notification unitgenerates implementation status information indicating incompletion of the procedure. Then, the notification unitnotifies the terminal deviceof the implementation status information (S). Thereafter, the terminal deviceperforms the processing of S.
121 100 200 7 FIG.A After the processing of Sis performed in the terminal device, the provider serverperforms the process similar to that in.
200 200 200 100 117 7 FIG.B 7 FIG.B Next, exemplary operation of the provider serverwill be further described.is a flowchart for explaining second exemplary operation of the provider server. Specifically,illustrates an operation to be performed by the provider serverafter the terminal deviceperforms the processing of S.
210 200 100 205 230 206 200 100 100 200 The reception unitof the provider serverreceives, from the terminal device, the first biological information, the second biological information, and the authentication result (S). The authentication unitcarries out authentication processing based on the first biological information and the second biological information (S). For example, the biometric authentication engine of the provider servermay have better performance than that of the biometric authentication engine of the terminal device. In view of the above, when the authentication fails in the terminal device, the provider servermay perform the authentication processing.
230 207 220 100 208 100 118 Then, the authentication unitgenerates an external authentication result indicating the authentication result (S). The notification unitnotifies the terminal deviceof the external authentication result (S). Thereafter, the terminal deviceperforms the processing of S.
1000 108 109 103 111 The present exemplary operation is merely an example, and the operation of the identity verification assistance systemis not limited to the operation described above. The order of the processing may be changed as appropriate. For example, the processing of Sand Sfor acquiring the first biological information may be performed at a timing earlier than that in the example described above. The processing of Sto Smay be performed before the document information is generated.
In the exemplary operation described above, the exemplary operation of the identity verification performed when the user carries out a predetermined procedure has been described. Thus, the exemplary operation includes the generation and transmission/reception of the document information associated with the procedure. If only the identity verification is first carried out at the time of the procedure, the processing associated with the generation, transmission/reception, and the like of the document information may not be performed.
100 100 100 As described above, the terminal deviceaccording to the second example embodiment measures the body or voice of the user at the time of authenticating the user, acquires the first biological information that is the biological information according to the result of the measurement, and further acquires the second biological information that is the biological information relevant to the body or voice of the person and the electronic certificate indicating the authenticity of the person, which are stored in the information storage medium. The terminal deviceauthenticates the user by the comparison based on the first biological information and the second biological information. Then, when the user is authenticated, the terminal devicetransmits the acquired electronic certificate and the authentication result.
100 100 In a case of performing the identity verification using a captured image of an official certificate attached with a facial portrait, the identity verification may not be accurately carried out if the surface of the official certificate is damaged. On the other hand, the terminal deviceaccording to the second example embodiment uses the biological information including the electronic certificate indicating the authenticity of the person stored in the information storage medium. Thus, the terminal deviceis enabled to carry out the identity verification without considering the state of the surface of the official certificate.
100 100 100 The terminal deviceis capable of performing authentication based on possession of the information storage medium storing the electronic certificate described above and performing authentication using the biological information stored in the information storage medium. Thus, the terminal deviceis enabled to reduce the risk of impersonation due to forgery of an official certificate or the like. That is, the terminal deviceaccording to the second example embodiment is capable of appropriately performing the identity verification.
100 100 When the user is not authenticated, the terminal devicemay transmit the first biological information and the second biological information to a server capable of performing authentication processing. Then, the terminal devicemay transmit the electronic certificate when it receives information indicating a result of the authentication processing based on the first biological information and the second biological information and the received result indicates that the user has been authenticated.
100 100 100 The authentication processing may fail in the terminal device. Meanwhile, an external server may include an authentication engine having better performance than that of the terminal device. In such a case, the terminal devicemay cause the external server to perform the authentication processing, whereby the identity verification may be carried out more appropriately.
100 The terminal devicemay transmit the electronic certificate and the authentication result to a server that accepts the procedure performed by the user, and may receive implementation status information indicating an implementation status of the procedure based on the transmitted electronic certificate and authentication result. As a result, the user may be notified of the implementation status of the procedure.
100 100 100 100 The terminal devicemay generate document information associated with the procedure, and may further transmit the document information when the user is authenticated. At this time, the terminal devicemay acquire the private key and the public key relevant to the private key stored in the information storage medium, and may encrypt the document information based on the private key. Then, when the user is authenticated, the terminal devicemay transmit the public key and the encrypted document information. With this arrangement, the terminal devicemay also be applied to a personal authentication service based on a public key cryptosystem.
100 100 When the user authentication fails in the terminal device, the terminal devicemay perform the authentication processing a predetermined number of times.
111 100 108 180 110 110 130 For example, it is assumed that the user is not authenticated in the processing of S. At this time, the terminal devicemay return to the processing of S. That is, the imaging unitimages the face of the user again. The first acquisition unitacquires a captured image imaged again. In other words, the first acquisition unitre-acquires, as the first biological information, biological information different from the previously acquired first biological information. Then, the authentication unitmay authenticate the user by comparison between the re-acquired first biological information and the second biological information.
100 111 If the number of times the user fails to be authenticated (i.e., number of authentication failures) exceeds a predetermined number of times, the terminal devicemay proceed to the processing of “No” in S.
130 The authentication unitmay generate an authentication result including the number of authentication failures. With this arrangement, the service provider may be notified of the number of authentication failures. The service provider is enabled to consider the information regarding the number of times in the procedure.
100 As described above, when the user is not authenticated, the terminal deviceaccording to the first modification may acquire the first biological information of the user again, and may authenticate the user by the comparison between the re-acquired first biological information and the second biological information.
The exemplary case of using a facial image as biological information has been described in the example embodiments above. An example of the biological information is not limited to this example. The biological information may be voice information, an iris image, a retinal image, fingerprint information, or the like. That is, voiceprint authentication, iris authentication, retinal authentication, fingerprint authentication, or the like may be carried out as the authentication processing.
100 110 120 130 For example, when the biological information is voice information, the voice of the user is measured by a microphone of the terminal device. The first acquisition unitacquires voice information relevant to the measured voice as the first biological information. The information storage medium stores voice information indicating the voice of the user in advance. The second acquisition unitacquires the stored voice information as the second biological information. Then, the authentication unitcarries out voiceprint authentication based on the first biological information and the second biological information.
As described above, various types of biometric authentication may be applied in the present disclosure.
[Third modification]
The exemplary case where the information storage medium is an official certificate, such as an individual number card, has been described in the example embodiments above. The information storage medium is not limited to this example.
100 100 100 For example, the information storage medium may be a storage medium included in the terminal device. That is, the terminal devicemay have the electronic certificate and the biological information of the user. In other words, the terminal devicemay be a device having a function of an official certificate, such as an individual number card.
100 300 200 300 The exemplary case where the terminal devicecauses the verification serverto verify the validity of the electronic certificate has been described in the example embodiments above. It is not limited to this example, and the provider servermay cause the verification serverto verify the validity.
201 210 200 300 210 300 200 202 220 100 For example, after the processing of S, the reception unitof the provider servertransmits the electronic certificate to the verification server. Then, the reception unitreceives a verification result regarding the validity of the electronic certificate from the verification server. If the validity of the electronic certificate is verified, the provider serverperforms the processing of Sand subsequent steps. If the validity of the electronic certificate is not verified, the notification unitnotifies the terminal deviceof implementation status information indicating incompletion of the procedure.
100 106 107 In this case, the terminal devicedoes not necessarily perform the processing of Sand S.
The method of acquiring the second biological information is not limited to the example described above.
100 120 Specifically, the information storage medium may not store the biological information. For example, an external server stores a database of facial images of persons in advance. The external server operates a website that may access personal information including facial images. The terminal devicelogs in to the website using the electronic certificate acquired from the information storage medium. Then, the second acquisition unitmay acquire a facial image through the website.
Next, an identity verification assistance system according to a third example embodiment will be described. In the third example embodiment, an exemplary function of the identity verification assistance system will be further described. Description of contents overlapping with the contents described in the first and second example embodiments will be partially omitted.
While an exemplary case where biological information is a facial image will be described also in the present example embodiment, the biological information is not limited to this example as described above.
8 FIG. 8 FIG. 1001 1001 101 200 is a block diagram illustrating an exemplary functional configuration of an identity verification assistance systemaccording to the third example embodiment. As illustrated in, the identity verification assistance systemincludes a terminal deviceand a provider server.
101 111 120 130 140 101 150 160 170 181 The terminal deviceincludes a first acquisition unit, a second acquisition unit, an authentication unit, and a transmission unit. The terminal devicefurther includes a document generation unit, an encryption unit, a receiving unit, and an imaging unit.
111 111 The first acquisition unitmay acquire biological information of a user as appropriate. Specifically, the first acquisition unitacquires third biological information at a timing different from the timing at which first biological information to be used for identity verification is acquired.
111 111 111 101 181 181 101 111 181 Specifically, the first acquisition unitmay acquire the third biological information at a predetermined timing before the first biological information is acquired. For example, it is assumed that the first acquisition unitacquires a facial image as the first biological information. Prior to that, the first acquisition unitacquires a facial image of the user operating the terminal device. In this case, the imaging unitimages the face of the user before capturing the facial image that serves as the first biological information. For example, the imaging unitimages the face of the user when an application for performing a procedure of the terminal deviceis activated. Then, the first acquisition unitacquires, as the third biological information, the facial image captured by the imaging unit.
111 101 181 101 Likewise, the first acquisition unitmay acquire the third biological information at a predetermined timing after the first biological information is acquired. At this time, the terminal devicemay or may not display the image being captured by the imaging unit. When the user is performing an operation related to the procedure, the image being captured may be displayed on a part of the display of the terminal device.
111 101 As described above, the first acquisition unitmay acquire the third biological information of the user operating the terminal deviceat a timing different from the timing at which the first biological information is acquired.
131 131 An authentication unitauthenticates the user by comparison based on the first biological information and the third biological information. That is, the authentication unitmay carry out authentication processing different from the authentication based on the first biological information and the second biological information. The authentication based on the first biological information and the second biological information is to verify whether the user is a person indicated by an information storage medium. On the other hand, the authentication based on the first biological information and the third biological information is to verify whether the user making an operation is the same.
Here, the authentication based on the first biological information and the second biological information will be referred to as first authentication. The authentication based on the first biological information and the third biological information will be referred to as second authentication.
111 131 The first acquisition unitmay acquire the third biological information multiple times. The authentication unitmay carry out the second authentication in response to acquisition of the third biological information.
1001 101 200 Exemplary operation of the identity verification assistance systemwill be described. In the present exemplary operation, operation of each of the terminal deviceand the provider serverwill be described. Description of processing similar to that of the second example embodiment will be partially omitted.
9 FIG. 6 FIG.A 101 101 101 181 301 110 180 302 102 109 is a flowchart for explaining exemplary operation of the terminal device. First, an application is activated in the terminal deviceby an operation made by the user (S). Then, the imaging unitimages the face of the user (S). The first acquisition unitacquires, as the third biological information, the captured image imaged by the imaging unit(S). The processing of Sto Sis similar to the example of.
130 303 130 The authentication unitcarries out authentication processing (S). Specifically, the authentication unitcarries out the first authentication based on the first biological information and the second biological information, and the second authentication based on the first biological information and the second biological information.
304 101 304 305 101 112 305 101 6 FIG.B If the user is not authenticated in the second authentication (“No” in S), the terminal devicemay terminate the process. If the user is authenticated in the second authentication (“Yes” in S) and the user is authenticated in the first authentication (“Yes” in S), the terminal devicemay perform the processing of Sand subsequent steps. If the user is not authenticated in the first authentication (“No” in S), the terminal devicemay perform the operation in.
101 101 As described above, the terminal deviceaccording to the third example embodiment may measure the body or voice of the user operating the terminal device itself at a timing different from the timing at which the first biological information is acquired, and may acquire the third biological information, which is biological information according to a result of the measurement. Then, the terminal devicemay authenticate the user by the comparison based on the first biological information and the third biological information.
101 A third party other than the legitimate user may swap during the operation related to the procedure, and may impersonate the legitimate user. On the other hand, the authentication based on the first biological information and the third biological information is to verify whether the user making the operation is the same. Thus, the terminal deviceaccording to the third example embodiment is capable of suppressing such impersonation of the user.
10 FIG. 10 FIG. 90 90 Hardware constituting the identity verification assistance system according to the first, second, and third example embodiments described above will be described.is a block diagram illustrating an exemplary hardware configuration of a computer device that implements the identity verification assistance system according to each example embodiment. In a computer device, the identity verification assistance system and the identity verification assistance method described in each example embodiment and each modification are implemented. More specifically, the identity verification assistance system and the identity verification assistance method described in each example embodiment and each modification are implemented in the computer device. For example, each of the terminal device, the provider server, and the like described in each example embodiment and each modification may have the hardware configuration illustrated in.
10 FIG. 90 91 92 93 94 95 96 97 As illustrated in, the computer deviceincludes a processor, a random access memory (RAM), a read only memory (ROM), a storage device, an input/output interface, a bus, and a drive device. The terminal device and the provider server may be implemented by multiple electric circuits.
94 98 91 98 92 98 91 98 98 93 98 80 97 90 6 6 7 7 9 FIGS.A,B,A,B, and The storage devicestores a program (computer program). The processorexecutes the programof the identity verification assistance system using the RAM. Specifically, for example, the programincludes a program that causes a computer to execute the process illustrated in. Functions of individual components of the identity verification assistance system are implemented in response to the processorexecuting the program. The programmay be stored in the ROM. The programmay be recorded in a storage mediumand read using the drive device, or may be transmitted from an external device (not illustrated) to the computer devicevia a network (not illustrated).
95 99 95 96 The input/output interfaceexchanges data with a peripheral device (keyboard, mouse, display device, etc.). The input/output interfacefunctions as a means for acquiring or outputting data. The busconnects individual components.
There are various modifications of the method of implementing the identity verification assistance system. For example, the identity verification assistance system may be implemented as a dedicated device. The identity verification assistance system, the terminal device, and the provider server may be implemented based on a combination of multiple devices.
Processing methods of causing a storage medium to record a program for implementing each component in the functions of each example embodiment, reading the program recorded in the storage medium as a code, and executing the program in a program are also included in the scope of each example embodiment. That is, a computer-readable storage medium is also included in the scope of each example embodiment. The storage medium recording the program described above and the program itself are also included in each example embodiment.
The storage medium is, for example, a floppy (registered trademark) disk, a hard disk, an optical disk, a magneto-optical disk, a compact disc (CD)-ROM, a magnetic tape, a nonvolatile memory card, or a ROM, but is not limited to this example. The program recorded in the storage medium is not limited to a program that executes processing by itself, and programs that operate on an operating system (OS) to execute processing in cooperation with other software and functions of an extension board are also included in the scope of each example embodiment.
While the present invention has been particularly shown and described with reference to example embodiments thereof, the present invention is not limited to these example embodiments. It will be understood by those of ordinary skill in the art that various changes in form and details may be made therein without departing from the spirit and scope of the present invention as defined by the claims.
The example embodiments and modifications described above may be appropriately combined.
Some or all of the example embodiments described above may be described as the following Supplementary Notes, but are not limited to the following.
a first acquisition means for measuring a body or voice of a user when authenticating the user and acquiring first biological information, the first biological information being biological information according to a result of the measurement; a second acquisition means for acquiring second biological information and an electronic certificate indicating authenticity of a person, the second biological information being biological information relevant to a body or voice of the person, the second biological information and the electronic certificate being stored in an information storage medium; an authentication means for authenticating the user by comparison based on the first biological information and the second biological information; and a transmission means for transmitting the acquired electronic certificate and an authentication result when the user is authenticated. A terminal device including:
a receiving means, in which when the user is not authenticated, the transmission means transmits the first biological information and the second biological information to a server capable of performing authentication processing, the receiving means receives information indicating a result of the authentication processing based on the first biological information and the second biological information, and when the received result indicating the user has been authenticated, the transmission means transmits the electronic certificate. The terminal device according to Supplementary Note 1, further including:
the first acquisition means measures the body or voice of the user operating the terminal device at a timing different from a timing at which the first biological information is acquired, and acquires third biological information, the third biological information being biological information according to a result of the measurement, and the authentication means authenticates the user by comparison based on the first biological information and the third biological information. The terminal device according to Supplementary Note 1 or 2, in which
a receiving means, in which the transmission means transmits the electronic certificate and the authentication result to a server accepting a procedure performed by the user, and the receiving means receives implementation status information indicating an implementation status of the procedure based on the electronic certificate and the authentication result that have been transmitted. The terminal device according to any one of Supplementary Notes 1 to 3, further including:
a document generation means for generating document information associated with the procedure, in which the transmission means further transmits the document information when the user is authenticated. The terminal device according to any one of Supplementary Notes 1 to 4, further including:
an encryption means for encrypting the document information, in which the second acquisition means acquires a private key and a public key relevant to the private key stored in the information storage medium, the encryption means encrypts the document information based on the private key, and when the user is authenticated, the transmission means transmits the public key and the encrypted document information. The terminal device according to Supplementary Note 5, further including:
when the user is not authenticated, the document generation means temporarily stores the generated document information. The terminal device according to Supplementary Note 5 or 6, in which
in a terminal operated by a user, measuring a body or voice of the user when authenticating the user and acquiring first biological information, the first biological information being biological information according to a result of the measurement; acquiring second biological information and an electronic certificate indicating authenticity of a person, the second biological information being biological information relevant to a body or voice of the person, the second biological information and the electronic certificate being stored in an information storage medium; authenticating the user by comparison based on the first biological information and the second biological information; and transmitting the acquired electronic certificate and an authentication result when the user is authenticated. An identity verification assistance method including:
in a terminal operated by a user, measuring a body or voice of the user when authenticating the user and acquiring first biological information, the first biological information being biological information according to a result of the measurement; acquiring second biological information and an electronic certificate indicating authenticity of a person, the second biological information being biological information relevant to a body or voice of the person, and an electronic certificate indicating authenticity of the person, the second biological information and the electronic certificate being stored in an information storage medium; authenticating the user by comparison based on the first biological information and the second biological information; and transmitting the acquired electronic certificate and an authentication result when the user is authenticated. A computer-readable storage medium storing a program for executing a process including:
100 101 ,terminal device 110 111 ,first acquisition unit 120 second acquisition unit 130 131 ,authentication unit 140 transmission unit 150 document generation unit 160 encryption unit 170 receiving unit 180 181 ,imaging unit 200 provider server 210 reception unit 220 notification unit 230 authentication unit 300 verification server 1000 1001 ,identity verification assistance system
Cooperative Patent Classification codes for this invention. Click any code to explore related patents in that topic.
January 10, 2023
July 30, 2026
Browse 5M+ US patents with plain-English claim translations and AI-generated analysis.